Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfblocker defend rdp/rds brute force attacks

    Scheduled Pinned Locked Moved pfBlockerNG
    5 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jogovogo
      last edited by jogovogo

      Hello everybody,

      somehow I will not be smart from the whole guide ...

      What is the easiest way to block an attack from ip4 addresses? (Terminal with rds)

      Ibound / or outbound rules?

      For example, if I enable geoip blocking on a country-by-country basis, outlook (exchange online) will stop working.

      I think because the ms servers are partly in the usa ...

      Someone a simple idea?

      Many thanks in advance!

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        You can either whitelist only those addresses that are allowed in, or you can put it all behind a VPN. I always try to avoid hanging services out on the Internet.

        1 Reply Last reply Reply Quote 0
        • J
          jogovogo
          last edited by

          Hi,

          we already had that.

          Vpn is not comfortable for the user.
          The connection takes place via pc / mobile / etc. devices.

          These get usually every 4-24 hours a new ip and there are many external users ...

          It's about the connection from the internet.
          I assumed that you can use this addon exactly for such a scenario. Only I will not be smart, how?

          We have rds blocker on the servers themselves, behind pfsense.

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Snort or Suricata will try to catch exploits as they enter your network. I don't use them so don't ask me how to configure. Other than that there isn't much you can do from a pfSense perspective.

            1 Reply Last reply Reply Quote 0
            • chpalmerC
              chpalmer
              last edited by

              Security through obscurity.. (if you believe that..)

              Use a different port number. That will keep some of it down.

              Triggering snowflakes one by one..
              Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.